Re: [PATCH] HID: core: fix OOB read of field->usage in hid_set_field()

Jiri Kosina <[email protected]>
Newsgroups gmane.linux.kernel.input,gmane.linux.kernel,gmane.linux.kernel.stable
Message-ID <[email protected]>
On Sun, 26 Jul 2026, Baul Lee wrote:

> hid_set_field() hands field->usage + offset to hid_dump_input() before
> the guard that bounds offset:
> 
> 	hid_dump_input(field->report->device, field->usage + offset, value);
> 
> 	if (offset >= field->report_count) {
> 		hid_err(...);
> 		return -1;
> 	}
> 
> Under CONFIG_DEBUG_FS hid_dump_input() dereferences that pointer, with
> buf = hid_resolv_usage(usage->hid, NULL).  The usage[] array is
> allocated inline with the hid_field in hid_register_field() and holds
> field->maxusage entries, so an offset past it reads off the end of the
> kvzalloc()ed allocation and into a neighbouring object.  Had the guard
> run first, offset < report_count <= maxusage would already have confined
> the pointer to the array.
> 
> A caller supplies such an offset today.  picolcd_fb_send_tile()
> validates only report->maxfield before issuing
> hid_set_field(report->field[0], 11 + i, ...) for i = 0..31, so its
> offsets are fixed at 11..42 and are never checked against the bound
> field.  When the device registers that field with fewer usages, the
> framebuffer deferred-io work drives the read on every tile.  KASAN
> reports a 4-byte slab-out-of-bounds read in hid_dump_input() below
> hid_set_field(), and the same boot logs "offset (1) exceeds
> report_count (1)" from the guard that runs only afterwards.
> 
> Move the hid_dump_input() call below the guard.  Because
> field->maxusage >= field->report_count, the guard then establishes that
> field->usage + offset lies inside the array before it is dereferenced,
> for every caller and without changing behaviour on the valid path.
> 
> Discovered by XBOW, triaged by Baul Lee <[email protected]>
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Reported-by: Federico Kirschbaum <[email protected]>
> Reported-by: Baul Lee <[email protected]>
> Cc: [email protected]
> Signed-off-by: Baul Lee <[email protected]>

Good catch. Applied, thanks.

-- 
Jiri Kosina
SUSE Labs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.